Description
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0821 | In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user. |
Github GHSA |
GHSA-rqj9-cq6j-958r | Arbitrary Command Execution in Hadoop |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T08:17:09.256Z
Reserved: 2018-06-05T00:00:00.000Z
Link: CVE-2018-11766
No data.
Status : Modified
Published: 2018-11-27T14:29:00.260
Modified: 2024-11-21T03:43:59.313
Link: CVE-2018-11766
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA